Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
2 malware familiesExploits CVEs in the wild

UNC6148

Also known asunc6148

UNC6148 is a suspected financially motivated threat actor tracked by Google Threat Intelligence Group (GTIG). The actor has been observed targeting fully patched, end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances, with activity reported as ongoing since at least October 2024. GTIG assessed that UNC6148 likely leveraged previously stolen valid administrative credentials, including in some reporting stolen credentials and OTP seeds from prior breaches, to establish SSL VPN sessions and deploy malware on SMA appliances. GTIG also assessed with moderate confidence that UNC6148 may have used an unknown zero-day remote code execution vulnerability to deploy OVERSTEP on opportunistically targeted SonicWall SMA appliances, though the initial credential acquisition method remains unknown. UNC6148 deploys OVERSTEP, described in the content as a previously unknown persistent backdoor and rootkit targeting SonicWall SMA 100 devices. Reporting in the provided content describes OVERSTEP as modifying the boot process for persistence, concealing its components, removing log entries to evade detection, establishing a reverse shell, stealing sensitive files and credentials, including administrator credentials, session tokens, OTP seeds, persist.database, and certificate material, and enabling privileged control of the appliance. The actor has also been described as using a kernel-level rootkit or persistent backdoor rootkit to remain stealthily resident on compromised systems. The group’s observed tradecraft includes using stolen credentials to establish VPN sessions, deploying backdoors on SMA 100 devices, maintaining persistence across reboots, clearing or manipulating logs, and enabling follow-on actions such as command execution, credential theft, data exfiltration, and extortion. GTIG noted possible exploitation of known SonicWall SMA vulnerabilities in related intrusion chains, including CVE-2021-20038, CVE-2021-20035, CVE-2021-20039, CVE-2024-38475, and CVE-2025-32819, while also not ruling out undisclosed vulnerability use. The content links UNC6148 to ransomware and extortion activity. It is described as associated with World Leaks, alongside Hive Ransomware and Secp0 Ransomware, and separate reporting cited in the content notes overlaps or links to Abyss-related ransomware incidents. The content also states UNC6148 may deploy OVERSTEP possibly for ransomware operations. No nation-state attribution is provided in the supplied content. Known alias in the provided content: UNC6148.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics11 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078×2
Valid Accounts
T1133×2
External Remote Services
T1190×3
Exploit Public-Facing Application
TA0003
Persistence
2 techniques
T1078×2
Valid Accounts
T1133×2
External Remote Services
TA0004
Privilege Escalation
1 technique
T1078×2
Valid Accounts
TA0005
Stealth
1 technique
T1078×2
Valid Accounts
TA0010
Exfiltration
3 techniques
T1041
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.